Turn an indicator, CVE, or MITRE ATT&CK technique into a starter detection rule in the format your stack uses. Everything is generated deterministically in your browser — no accounts, no data leaves the page.
# ---------------------------------------------------------------
# Cyronix Threat Intelligence - generated detection TEMPLATE
# Format: Sigma | Input: CVE CVE-2026-42018
# STATUS: TEMPLATE - review, test, and tune before production use.
# Generated: 2026-10-05T13:49:15.053Z
# ---------------------------------------------------------------
title: Cyronix - Exploitation attempt CVE-2026-42018
status: experimental
description: Starter detection for exploitation attempts related to CVE-2026-42018. Tune to the affected product's logs.
logsource:
category: webserver
detection:
selection:
# TODO: add request patterns / payload signatures specific to CVE-2026-42018
cs-uri-query|contains: 'PLACEHOLDER_EXPLOIT_PATTERN'
condition: selection
level: high
tags:
- attack.initial_access
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-42018
These are deterministic starter templates, not AI-generated and not production-validated. Review, test against your log schema, and tune before deploying. Generated locally in your browser.
Each rule is a scaffold: it wires up the right structure and the indicator, but placeholders marked TODO must be filled with behavior specific to your environment, and field names must be matched to your log schema. Test in a staging pipeline before enabling in production. For 5 indicator types across six formats, start from an exploited CVE or a technique in the ATT&CK Explorer and generate a matching rule.
No. They are produced by deterministic templates, so the same input always yields the same output. They are starter scaffolds, not AI guesses, and are explicitly not production-validated.
Not safely. Each rule contains placeholders and generic field names that must be adapted to your environment and log schema, then tested. Treat the output as a well-structured starting point that saves you boilerplate.
Sigma, YARA, Suricata, Snort, KQL for Microsoft Sentinel and Defender, and Splunk SPL. The available formats change based on the indicator type — for example, YARA is offered for file hashes, and Suricata/Snort for network indicators.
No. Rule generation runs entirely client-side. Your indicators are never transmitted, logged, or stored.